Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-45418 |
|
Path Traversal in path-traversal (CVE-2021-45418)
path traversal in path-traversal (CVE-2021-45418). Successful exploitation can lead to full system takeover.
|
| CVE-2020-20426 |
|
Cross-Site Scripting (XSS) in s-cms (CVE-2020-20426)
cross-site scripting in s-cms (CVE-2020-20426). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-45105 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.1` or later.
|
| CVE-2021-26787 |
|
Cross-Site Scripting (XSS) in genesys (CVE-2021-26787)
cross-site scripting in genesys (CVE-2021-26787). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-36450 |
|
Cross-Site Scripting (XSS) in verint (CVE-2021-36450)
cross-site scripting in verint (CVE-2021-36450). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-43256 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2021-43875 |
|
Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
|
| CVE-2018-10228 |
|
Cross-Site Scripting (XSS) in limesurvey (CVE-2018-10228)
cross-site scripting in limesurvey (CVE-2018-10228). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-4104 |
|
Unsafe Deserialization in apache (CVE-2021-4104)
vulnerability in apache (CVE-2021-4104). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12149 KEV |
|
[KEV] Unsafe Deserialization in Red hat red-hat (CVE-2017-12149)
vulnerability in Red hat red-hat (CVE-2017-12149). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41449 |
|
Path Traversal in path-traversal (CVE-2021-41449)
path traversal in path-traversal (CVE-2021-41449). Confidential information can be exposed externally.
|
| CVE-2021-41450 |
|
Vulnerability in dos (CVE-2021-41450)
vulnerability in dos (CVE-2021-41450). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-19611 |
|
Cross-Site Scripting (XSS) in racktables-project (CVE-2020-19611)
cross-site scripting in racktables-project (CVE-2020-19611). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-44149 |
|
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resu...
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operat...
|
| CVE-2021-43687 |
|
Cross-Site Scripting (XSS) in chamilo (CVE-2021-43687)
cross-site scripting in chamilo (CVE-2021-43687). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-4019 |
|
vim is vulnerable to Heap-based Buffer Overflow
vim is vulnerable to Heap-based Buffer Overflow
|
| CVE-2021-43221 |
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
| CVE-2021-24713 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2021-24713)
cross-site scripting in wordpress (CVE-2021-24713). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-41436 |
|
Vulnerability in dos (CVE-2021-41436)
vulnerability in dos (CVE-2021-41436). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-41164 |
|
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
|
| CVE-2021-42321 KEV |
|
[KEV] Vulnerability in Microsoft exchange (CVE-2021-42321)
vulnerability in Microsoft exchange (CVE-2021-42321). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-43208 |
|
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43209.
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43209.
|
| CVE-2021-43209 |
|
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43208.
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43208.
|
| CVE-2021-42316 |
|
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
|
| CVE-2021-42296 |
|
Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
|
| CVE-2021-42298 |
|
Microsoft Defender Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
|
| CVE-2021-42284 |
|
Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
|
| CVE-2021-42274 |
|
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
|
| CVE-2021-42275 |
|
Microsoft COM for Windows Remote Code Execution Vulnerability
Microsoft COM for Windows Remote Code Execution Vulnerability
|
| CVE-2021-42276 |
|
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
|
| CVE-2021-41378 |
|
Windows NTFS Remote Code Execution Vulnerability
Windows NTFS Remote Code Execution Vulnerability
|
| CVE-2021-41372 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2021-41372)
cross-site scripting in csrf (CVE-2021-41372). Confidential information can be exposed externally.
|
| CVE-2021-41368 |
|
Microsoft Access Remote Code Execution Vulnerability
Microsoft Access Remote Code Execution Vulnerability
|
| CVE-2021-41356 |
|
Windows Denial of Service Vulnerability
Windows Denial of Service Vulnerability
|
| CVE-2021-40442 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2021-38666 |
|
Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
|
| CVE-2021-26443 |
|
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
|
| CVE-2020-25366 |
|
Vulnerability in dos (CVE-2020-25366)
vulnerability in dos (CVE-2020-25366). Data can be tampered with by attackers.
|
| CVE-2021-38647 KEV |
|
[KEV] Vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-34473 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-34473)
SSRF in Microsoft exchange-server (CVE-2021-34473). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2021-34527 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2021-34527)
vulnerability in Microsoft windows (CVE-2021-34527). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-40444 KEV |
|
[KEV] Path Traversal in Microsoft mshtml (CVE-2021-40444)
path traversal in Microsoft mshtml (CVE-2021-40444). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27085 KEV |
|
[KEV] Vulnerability in Microsoft internet-explorer (CVE-2021-27085)
vulnerability in Microsoft internet-explorer (CVE-2021-27085). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27059 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2021-27059)
vulnerability in Microsoft office (CVE-2021-27059). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26855 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-26855)
SSRF in Microsoft exchange-server (CVE-2021-26855). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26858 KEV |
|
[KEV] Vulnerability in Microsoft exchange-server (CVE-2021-26858)
vulnerability in Microsoft exchange-server (CVE-2021-26858). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27065 KEV |
|
[KEV] Path Traversal in Microsoft exchange-server (CVE-2021-27065)
path traversal in Microsoft exchange-server (CVE-2021-27065). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1675 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2021-1675)
vulnerability in Microsoft windows (CVE-2021-1675). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26857 KEV |
|
[KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2021-26857)
vulnerability in Microsoft exchange-server (CVE-2021-26857). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3992 KEV |
|
[KEV] Use-After-Free in Vmware esxi (CVE-2020-3992)
vulnerability in Vmware esxi (CVE-2020-3992). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|